Incident Response Tooling
Pharos by Helm
Read-only evidence collection for business and consumer email compromise investigations — bringing the available mailbox, account activity, and connected-app evidence into focus. Direct integrations for Google Workspace and Microsoft 365, with investigation support across other mail providers.
What It Is
Evidence Collection, Not Another Security Product
Pharos is a tool built and operated by Helm Information Security for use in our own business email compromise investigations. It is not a monitoring platform, a security scanner, or a mail client.
When an email account is compromised, the evidence that matters is scattered across mailbox rules, message headers and content, sign-in history, administrative activity, recovery settings, and connected applications. The exact evidence available varies by provider, but gathering it during an active incident is consistently slow and error-prone.
Pharos automates collection from supported platforms and gives our investigators a consistent process for provider-supplied evidence, so the investigation starts with facts instead of guesswork.
What It Collects
- Mail filters, forwarding addresses, delegation, and recovery settings where available
- Message headers and content for the specific mailboxes and date ranges under investigation
- Sign-in and account activity, including IP addresses, geography, and authentication details where available
- Connected-application and delegated-access records exposed by the provider
- Administrative, sharing, and security-setting changes for managed business environments
- Account and directory information needed to establish the scope of the incident
How It Works
Authorized by your organization or the account owner, scoped to the incident, and revocable where direct access is used.
Pharos is only used inside a signed engagement. There is no self-service signup — access is provisioned per client, per incident.
For Google Workspace and Microsoft 365, the collection application is deployed inside your own Google Cloud project or Microsoft tenant as an internal application of your organization. Your administrators own it, grant it the permissions the investigation needs, and can revoke it at any time. Your organization's mail is never reached through an application published by Helm. For consumer accounts, the account owner gathers evidence using the exports and security records the provider makes available, with our guidance. We explain what evidence is available before collection begins.
Collection is read-only and bounded by the mailboxes and date range agreed in the engagement letter. The app never sends mail, never modifies settings, and never deletes anything.
We deliver the investigation report. Any direct application authorization is revoked through the relevant provider, and collected data is retained or destroyed on the schedule set in the engagement letter.
Email Provider Coverage
The investigation follows the evidence each provider makes available. Access method and collection depth vary by platform.
Direct, administrator-authorized collection of Gmail messages and settings, Workspace audit activity, connected applications, and directory information relevant to the investigation. The application is deployed as an internal app in your own Google Cloud project, so your administrators own it and can revoke it without involving us.
Direct, administrator-authorized collection from Exchange Online, Entra ID, Microsoft Graph, and the unified audit log for the accounts and period under investigation.
Investigation support for Gmail, Outlook.com and Hotmail, Yahoo Mail, AOL Mail, and other providers using the account records, exports, and security evidence each service makes available. The account owner retrieves this evidence, such as data exports, sign-in history, and forwarding and recovery settings, with our guidance. No third-party application access to the account is required.
Pharos uses provider permissions only for read operations and does not send, modify, or delete mail or change customer account settings. Remediation is performed by the client or account owner, with our guidance.
How We Handle Investigation Data
These controls apply to evidence collected from Google Workspace, Microsoft 365, and other mail providers. Investigation evidence is some of the most sensitive data an organization has, and we treat it accordingly.
All API access uses TLS. Collected evidence is stored encrypted at rest in an access-controlled case repository, separated per client engagement.
Only the Helm personnel assigned to your engagement can access your data. Access requires multi-factor authentication and is logged.
Evidence is retained for the period set in your engagement letter — to support insurance claims, law enforcement referrals, or litigation — then securely destroyed. You can request earlier deletion.
We do not sell or rent investigation data, and we never use it for advertising, marketing, or credit-related purposes. We share it only as permitted by your engagement agreement.
We do not use identifiable client or personal data to train generalized AI models. Where permitted, we may use de-identified or aggregated non-Google information that cannot reasonably be linked to a client or individual to improve security detections and analytical models. We do not use Google Workspace data obtained through Google APIs — including messages, settings, directory information, audit logs, or information derived from that data — to create, train, or improve generalized AI or machine learning models.
Where direct provider access is used, the client administrator or account owner can revoke that access through the provider. Revocation stops further collection but does not delete evidence already collected.
Support and Contact
Pharos is developed and operated by Helm Information Security, a cybersecurity consultancy based in Wisconsin. Questions about the application, its data handling, or an active authorization go to the same team that runs the investigations.
- Support and privacy inquiries: helminfosec.com/contact
- Phone: (608) 448-6075
- Active incident? Email us with INCIDENT in the subject line for priority response
Responding to a Compromise Now?
Pharos is one part of our email compromise response engagement. If an account is compromised today, start there — the tooling follows the engagement.
Email Compromise Response